← Vulnerability feed

Vulnerability record · CVE-2018-19000 · published 5 February 2019

CVE-2018-19000: Lcds laquis scada authentication bypass via alternate path vulnerability

Lcds · Laquis Scada

LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sensitive data.

5.3 CVSS 3.0 Medium EPSS 8.8% · top 5.0% CWE-288 · Authentication bypass via alternate pathCWE-287 · Improper authentication
5.3CVSS 3.0 base score, v2 5.0
8.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sensitive data.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/106634 Third Party AdvisoryVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-19-015-01 Third Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/106634 Third Party AdvisoryVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-19-015-01 Third Party AdvisoryUS Government Resource

Track CVE-2018-19000 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-18996Lcds laquis scada injection vulnerabilityLCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an attacker to …EPSS 2.5%9.8CVE-2018-18998Lcds laquis scada hard-coded credentials vulnerabilityLCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized access to the system with high pr…EPSS 2.4%9.8CVE-2018-17893Lcds laquis scada null pointer dereference vulnerabilityLAquis SCADA Versions 4.1.0.3870 and prior has an untrusted pointer dereference vulnerability, which may allow remote code execution.EPSS 6.4%9.8CVE-2018-17895Lcds laquis scada out-of-bounds read vulnerabilityLAquis SCADA Versions 4.1.0.3870 and prior has several out-of-bounds read vulnerabilities, which may allow remote code execution.EPSS 4.8%9.8CVE-2018-17897Lcds laquis scada integer overflow vulnerabilityLAquis SCADA Versions 4.1.0.3870 and prior has several integer overflow to buffer overflow vulnerabilities, which may allow remote code execution.EPSS 6.0%8.8CVE-2018-18992Lcds laquis scada injection vulnerabilityLCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an attacker to execute remote co…EPSS 2.0%8.8CVE-2018-18988Lcds laquis scada out-of-bounds read vulnerabilityLCDS Laquis SCADA prior to version 4.1.0.4150 allows execution of script code by opening a specially crafted report format file. This may allow remot…EPSS 2.6%8.8CVE-2018-17899Lcds laquis scada path traversal vulnerabilityLAquis SCADA Versions 4.1.0.3870 and prior has a path traversal vulnerability, which may allow remote code execution.EPSS 8.1%

Source: NIST National Vulnerability Database (record CVE-2018-19000), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.